CVE-2026-57963 Details
Description
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
A vulnerability in Mozilla Thunderbird allows attackers to inject arbitrary styled content, phishing links, and CSS that manipulates the chat user interface. This issue arises when HTML chat messages are sent through Matrix or XMPP. The vulnerability affects Thunderbird versions 140.12.0 and prior, as well as 152.0.0, and was reported by Michael Bommarito.
Users can upgrade to Thunderbird 152.0.1 or 140.12.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2042910 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-63/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-64/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla thunderbird | < 140.12.1 < 152.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Reanalysis | [email protected] |
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |